loader image

In many small businesses and community organisations, shared logins begin as a matter of convenience.
A general email address is created, several staff members are given the same password, and everyone signs in using those credentials. It may seem simple, particularly when the team is small.
However, a shared login is not the same as a properly configured shared mailbox. A shared mailbox allows several authorised staff members to manage a common address—such as accounts@ or reception@—while each person continues to sign in through their own individual account.
Shared logins create security, accountability and operational problems that tend to grow with the organisation.
A better approach is to give every staff member their own account while providing controlled access to the shared information they need.

Who actually signed in?

When several people use the same username and password, it becomes difficult to know who performed a particular action.

If an email is sent, a document is deleted or a setting is changed, the system may only record the common login—not the individual responsible.

This can make it much harder to:

  • Investigate mistakes or suspicious activity
  • Confirm who accessed sensitive information
  • Apply different permissions to different roles
  • Remove one person’s access without affecting everyone
  • Demonstrate appropriate governance and accountability

Individual accounts create a clearer record of activity and allow access to be managed according to each staff member’s responsibilities.

A shared email address does not require a shared login

Businesses often need addresses such as:

  • accounts@
  • admin@
  • reception@
  • support@
  • enquiries@

These addresses are useful and can continue to be used without sharing a password.

Microsoft 365 shared mailboxes allow authorised staff to access a common mailbox through their own individual accounts. Staff can read and respond to messages sent to the shared address, while the organisation retains control over who has access.

Microsoft’s guidance states that shared mailboxes are intended to be accessed through delegated permissions rather than by giving staff a password and asking them to sign in directly. More information is available in Microsoft’s shared mailbox guidance.

This provides the convenience of a common business address while preserving individual accountability.

Put simply: share the mailbox—not the login.

What happens when somebody leaves?

Shared logins are particularly risky when a staff member or volunteer leaves the organisation.

If that person knows the password to a common email address, cloud-storage service or other business system, they may retain access after their employment ends. Changing the password can help, but the new password must then be updated everywhere and redistributed to the remaining staff.

This process is easy to overlook, especially during a busy or unexpected departure.

With individual accounts, the departing person’s access can be disabled without changing how everyone else works. Their business email and files can then be preserved or transferred according to the organisation’s requirements.

A good offboarding process should consider:

  • Email and shared mailbox access
  • OneDrive, Teams and SharePoint files
  • Business applications
  • Company-owned computers and mobile devices
  • Saved passwords and authentication methods
  • Responsibility for unfinished work
  • Retention of important business records

The same principle applies when somebody joins the organisation or changes roles. Access should be deliberately granted, reviewed and removed rather than accumulating indefinitely.

Adding another layer with multifactor authentication

Even a strong password can be stolen.

A staff member might enter it into a convincing phishing website, reuse it on another service that is later breached or accidentally expose it in some other way.

Multifactor authentication—often shortened to MFA—requires an additional form of verification when somebody signs in. This might involve an authenticator application, a security key or another approved method.

MFA means that obtaining a password may not be enough for an attacker to access the account. The Australian Cyber Security Centre recommends enabling MFA on important accounts, including email and other services containing sensitive information. Its advice is available through cyber.gov.au.

Every staff member having an individual account also makes MFA practical. Each person can use their own authentication method instead of a team attempting to share access to one security prompt or device.

Making the change without disrupting the business

Moving away from shared logins does not need to happen all at once.

The first step is understanding which logins are being shared, who currently uses them and what business purpose each one serves. From there, individual accounts, shared mailboxes and appropriate permissions can be introduced progressively.

Staff also need a clear explanation of why the change is being made and how the new arrangement will work. A technically secure system will be less effective if people find it confusing and begin looking for ways around it.

The objective is to improve security while making everyday responsibilities clearer and easier to manage.

How Harvey IT Professionals can help

Harvey IT Professionals helps businesses and community organisations across North West NSW establish practical account and access-management processes.

We can assist with:

  • Identifying shared or unmanaged logins
  • Creating individual Microsoft 365 accounts for staff
  • Converting general email addresses into shared mailboxes
  • Configuring mailbox and file permissions
  • Introducing multifactor authentication
  • Establishing onboarding and offboarding procedures
  • Reviewing access when staff change roles
  • Providing staff training and ongoing support

We begin by understanding how the organisation currently works and then recommend improvements suited to its size, risks and priorities.

If your organisation relies on shared usernames or passwords, now is a good time to review who can access its systems and whether that access can be managed safely.

Coming next: Where should our files live?

In the next article, we will look at another common source of confusion: the difference between OneDrive, SharePoint and Microsoft Teams.

We will explain where individual and shared documents should be stored, how these Microsoft 365 services work together, and how a clear file structure can reduce duplication, lost documents and uncertainty about which version is current.